Courseiva
Security Profiles →mediumMultiple Choice

NSE4 Security Profiles Practice Question

A FortiGate administrator wants to block outgoing DNS requests to known malware domains. Which security profile should be used?

⚠ Common exam trap

A common mix-up: candidates confuse DNS Filter with Web Filter, assuming that blocking malicious domains is a web filtering function, but DNS Filter operates at the DNS protocol level and is the correct profile for blocking DNS requests to specific domains.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DNS filter

DNS Filter is the correct security profile because it is specifically designed to inspect and block DNS queries based on domain names, IP addresses, or categories. By configuring a DNS filter policy with a custom list of known malware domains, the FortiGate can intercept outgoing DNS requests and drop those matching the malicious entries, preventing the resolution of malware domains.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Application control

    Why it's wrong here

    Application control identifies traffic by application signatures and IP/port correlations, not by the QNAME inside a DNS query. DNS requests on UDP/53 carry only the queried domain in a binary format; app control cannot parse that field for domain blocking. It may block DNS protocol as a whole, but it cannot selectively block outgoing DNS to a malicious domain.

  • ✗

    Web filter

    Why it's wrong here

    Web filtering operates on HTTP/HTTPS requests, extracting the URL from the HTTP Host header or TLS SNI after a connection is established. A standard outgoing DNS query is a separate protocol on UDP port 53 with no HTTP URL for the web filter to evaluate. Thus web filter cannot block the DNS request itself; it would only be able to block subsequent web browsing to that domain.

  • ✗

    IPS

    Why it's wrong here

    IPS engines inspect DNS traffic for exploit signatures and protocol anomalies, such as malformed packets or tunneling indicators, but they do not implement per-domain policy lookup. IPS can flag a DNS response with an off-channel IP or a query attempting zone transfer, but it lacks FortiGuard category-based domain matching and cannot be configured to allow or deny specific domains. Therefore, while it may detect DNS abuse, it is not the right feature for blocking outgoing DNS requests to known-bad domains.

  • ✓

    DNS filter

    Why this is correct

    DNS filter is purpose-built to inspect outgoing DNS queries and compare the requested Fully Qualified Domain Name (FQDN) against FortiGuard DNS categories or an administrator-defined domain list. When a match occurs on a blocked category or domain, the filter can drop the query, return a synthetic NXDOMAIN, or redirect to a sinkhole IP to prevent resolution. This direct interception of the DNS request is why it is the correct feature for this requirement.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.